CVE Explorer
CVE-2026-22245
Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided domains. Mastodon, however, has some protection mechanism to disallow requests to local IP addresses (unless specified in `ALLOWED_PRIVATE_ADDRESSES`) to avoid the "confused deputy" problem. The list of disallowed IP address ranges was lacking some IP address ranges that can be used to reach local IP addresses. An attacker can use an IP address in t
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"mastodon","vendor":"mastodon","versions":[{"status":"affected","version":"< 4.2.29"},{"status":"affected","version":">= 4.3.0-beta.1, < 4.3.17"},{"status":"affected","version":">= 4.4.0-beta.1, < 4.4.11"},{"status":"affected","version":">= 4.5.0-beta.1, < 4.5.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:18479f6f5a1adf045fbbe3af1fd2ff4e9875ba7a824faba12d520bb68e7d6ad3 · sha256:585c034604e111e7… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:18479f6f5a1adf045fbbe3af1fd2ff4e9875ba7a824faba12d520bb68e7d6ad3 · sha256:585c034604e111e7… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:18479f6f5a1adf045fbbe3af1fd2ff4e9875ba7a824faba12d520bb68e7d6ad3 · sha256:585c034604e111e7… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/mastodon/mastodon/commit/0f4e8a6240b5af1f2c3f34d2793d8610c6ef2aca","tags":["x_refsource_MISC"],"url":"https://github.com/mastodon/mastodon/commit/0f4e8a6240b5af1f2c3f34d2793d8610c6ef2aca"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:18479f6f5a1adf045fbbe3af1fd2ff4e9875ba7a824faba12d520bb68e7d6ad3 · sha256:585c034604e111e7… · /containers/cna/references/1
{"name":"https://github.com/mastodon/mastodon/commit/17022907866710a72a1b1fc0a5ce9538bad1b4c3","tags":["x_refsource_MISC"],"url":"https://github.com/mastodon/mastodon/commit/17022907866710a72a1b1fc0a5ce9538bad1b4c3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:18479f6f5a1adf045fbbe3af1fd2ff4e9875ba7a824faba12d520bb68e7d6ad3 · sha256:585c034604e111e7… · /containers/cna/references/2
{"name":"https://github.com/mastodon/mastodon/commit/71ae4cf2cf5138ccdda64b1b1d665849b688686d","tags":["x_refsource_MISC"],"url":"https://github.com/mastodon/mastodon/commit/71ae4cf2cf5138ccdda64b1b1d665849b688686d"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:18479f6f5a1adf045fbbe3af1fd2ff4e9875ba7a824faba12d520bb68e7d6ad3 · sha256:585c034604e111e7… · /containers/cna/references/3
{"name":"https://github.com/mastodon/mastodon/security/advisories/GHSA-xfrj-c749-jxxq","tags":["x_refsource_CONFIRM"],"url":"https://github.com/mastodon/mastodon/security/advisories/GHSA-xfrj-c749-jxxq"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:18479f6f5a1adf045fbbe3af1fd2ff4e9875ba7a824faba12d520bb68e7d6ad3 · sha256:585c034604e111e7… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.